Guide
The AI Guardrail Playbook: Checklists, Review Gates, and Rules Your Team Will Actually Use
Not a 40-page policy nobody reads — a one-page playbook, three review tiers, and a 90-second checklist that sits between “AI drafted this” and “this is now live.”
AI will draft your emails, summarise your contracts, and answer your customers before a human ever sees the output, if you let it. That’s the point. The trouble starts when nobody checks the output before it goes out the door.
In February 2024, a tribunal in British Columbia found Air Canada liable for a refund policy its own chatbot made up on the spot.[1] In 2025, Deloitte had to repay part of a AU$440,000 government contract after a researcher found fabricated references in a report built with AI assistance.[2] Neither company set out to ship a mistake. Neither had a human check the output before a customer, or a government department, saw it.
None of this is an argument against using AI. LOKAL runs on it. Since 2017 we’ve trained more than 5,000 people across the Philippines and Australia, and in one 4,000-person rollout, 72% were using AI weekly within a month. What we’re arguing for is small and concrete: a few checkpoints between “AI drafted this” and “this is now live.” Not a policy binder nobody reads but a playbook your team will actually reach for.
What a guardrail actually is
A guardrail is not a 40-page AI acceptable-use policy sitting in a shared drive. It’s a specific rule that limits what AI can do without a person checking first. Useful guardrails read like this:
- AI can draft a client email. A human sends it.
- AI can summarise a contract. A human confirms anything that changes price, liability, or scope.
- AI can propose social copy. A human approves anything naming a competitor, a client, or a number.
- AI can answer common customer questions. A human reviews anything about refunds, pricing exceptions, or complaints.
That’s four rules, not a framework. Most small and mid-sized businesses need somewhere between five and fifteen of these, organised by where the risk actually sits and not a governance committee.
Guardrails are the second half of a pair. The first half is deciding what to hand over at all — which is the job of our Create, Understand, Act framework. Sort the task first, then set the checkpoint.
The three places AI mistakes ship
Nearly every public AI failure falls into one of three buckets. Knowing which bucket you’re exposed in tells you where to put your first guardrail.
1. Content and brand risk
AI writes something inaccurate, off-tone, or defamatory, and it goes out under your name. A blog post, a social caption, a client report. This is where hallucinated facts and fabricated citations live. It’s also the least dramatic-looking risk and the easiest to skip checking, which is exactly why it catches people out.
2. Data and privacy risk
A staff member pastes something they shouldn’t into a public AI tool. Customer records, financial figures, unreleased pricing, another client’s brief. Samsung’s engineers famously pasted proprietary source code into ChatGPT to help debug it; the data was gone the moment they hit enter.[3] This risk is invisible until it isn’t.
3. Decision and legal risk
AI’s output gets treated as fact in a document with real consequences. A legal brief, a compliance report, a customer commitment. This is the bucket that produced the Air Canada tribunal ruling and Deloitte’s repayment. It’s also the bucket where courts have now fined lawyers individually. In one March 2026 case, two attorneys were fined $15,000 each, plus the other side’s legal fees, for filing briefs with more than two dozen fabricated citations between them.[4]
Map your own AI use against these three before you write a single rule. Most businesses are more exposed in one bucket than the other two.
The one-page AI guardrail template
You don’t need a governance framework. You need one page, six sections, that a new hire can read in five minutes:
- 01
Stance
One sentence on how your business treats AI. For example: “AI drafts, humans decide and publish.”
- 02
Approved tools
Which AI tools staff can use for work, and on what account (never a personal login for company work).
- 03
Data rules
What can never go into a prompt — customer PII, financial data, unreleased material, anything under NDA — versus what’s fine: public information, general drafting, formatting help.
- 04
Human review points
The specific moments a person must check AI output before it moves forward (see the review gates below).
- 05
Disclosure
Where and when you tell clients or customers that AI was involved, even briefly.
- 06
Ownership
Who owns this document, who can update it, and how often it gets reviewed.
Print it, pin it in your team wiki, put it on page one of onboarding because a guardrail nobody has read is not a guardrail at all.
Review gates: a three-tier system
Not every piece of AI output carries the same risk, so not everything needs the same level of scrutiny. A simple three-tier system keeps this fast instead of bureaucratic:
| Tier | What it covers | Who checks it |
|---|---|---|
| Tier 1 — Low stakes, light check | Internal drafts, brainstorm lists, first-pass summaries | One person skims for obvious errors before anyone relies on it. No sign-off required. |
| Tier 2 — Customer- or public-facing | Blog posts, social captions, marketing emails, internal reports shared with a manager | A named reviewer checks facts, tone, and brand voice against the checklist below before it publishes. |
| Tier 3 — Legal, financial or reputational exposure | Anything quoting a price, making a promise, citing a source, going to a regulator, or representing the business externally at scale | Two people: one for accuracy, one for the actual decision to publish or send. No exceptions. |
Most businesses make the same mistake: they apply Tier 1 scrutiny to Tier 3 content because the AI output “looked confident.” But confidence isn’t accuracy. The 2023 case that started the legal profession’s AI reckoning proves it. A New York lawyer filed a ChatGPT-drafted brief citing six cases that didn’t exist,[5] and it happened for one reason: the writing looked polished enough that nobody thought to check.
Polish is not proof. Treat confident-sounding output as unverified until someone has actually checked it.
The pre-publish QC checklist
Before anything Tier 2 or Tier 3 goes live, run it through these checks. Ninety seconds, most of the time.
This is the same discipline LOKAL teaches inside its own practical AI skills training: AI is a co-pilot, not an autopilot. It drafts; a person checks the numbers, verifies the facts, and reviews the tone before anything ships.
Data-handling rules for staff
Keep this part plain-language, because vague rules get ignored and specific ones get followed.
| Never paste into a public AI tool | Generally safe |
|---|---|
| Customer personal information | Public information |
| Financial data | General work questions |
| Passwords or access credentials | Drafting help and formatting |
| Unreleased pricing or product details | Brainstorming |
| Anything covered by an NDA | Summarising documents already meant to be shared |
| Another client’s confidential brief | — |
Where a human must never be skipped
Regardless of tooling, four things always need a person, no shortcuts:
- Anything that commits the business — a price, a refund, a deadline, a guarantee, a contract term.
- Anything published externally under your name — blog content, press statements, client reports, social posts.
- Anything citing a source, case, statistic or quote — verify it exists and says what it’s claimed to say.
- Anything touching customer or employee personal data — a privacy review before it’s processed, not after.
This holds even as the tooling gets more capable. Agents that can reach your calendar, drive and CRM widen what “AI did it” covers — worth understanding before you set the rules, which is what our plain-English guide to agents, MCP and Skills is for.
Rolling this out without creating compliance theatre
A guardrail system fails the same way an AI pilot fails: it looks good in the launch meeting and nobody follows it three months later. Treat the rollout the way you’d treat any change management project such as assigning an owner, training the team on the actual document (not just an email announcing it), and checking back at 30, 60, and 90 days to see whether the review gates are actually being used or quietly skipped. That’s the same adoption discipline behind LOKAL’s own AI adoption and implementation work. The guardrails only count if people are still using them after the first month.
Sources
- Moffatt v. Air Canada, 2024 BCCRT 149 (B.C. Civil Resolution Tribunal, Feb. 14, 2024). canlii.org
- “Deloitte to refund government after using AI in $440k report,” Accounting Times, Oct. 9, 2025 — on the Department of Employment and Workplace Relations report, its fabricated academic references and misquoted Federal Court orders. accountingtimes.com.au (also reported by CFO Dive)
- “Samsung Bans ChatGPT Among Employees After Sensitive Code Leak,” Forbes, May 2, 2023. forbes.com
- Whiting v. City of Athens (6th Cir., March 2026); “Sixth Circuit Slaps Steep Sanctions on Two Lawyers for Fake Citations and Misrepresentations in Appellate Briefs,” LawSites, March 2026. lawnext.com
- Mata v. Avianca, Inc., No. 1:22-cv-01461, sanctions opinion (S.D.N.Y. June 22, 2023). law.justia.com
Every citation above was checked against its source before this piece was published — the same check the article asks you to run.
FAQ
Common questions
What is an AI guardrail, in plain terms?
A specific rule that limits what AI can do without a person checking first — for example, “AI can draft a client email, but a human sends it.”
Do we need a written AI policy if we’re a small team?
Yes, but it doesn’t need to be long. One page covering your stance, approved tools, data rules, review points, disclosure practice, and document ownership covers most small teams.
Who should have final sign-off on AI-generated content or decisions?
A named person, not “the team.” For anything Tier 2 or higher, one person checks accuracy and a second confirms the decision to publish or send — especially for anything that commits the business.
How do we check for AI hallucinations before publishing?
Verify every name, number, date, quote, and citation against a real, checkable source. Treat confident-sounding output as unverified until someone has actually checked it — polish is not proof.
What data should staff never paste into an AI tool?
Customer personal information, financial figures, passwords or access credentials, unreleased pricing, NDA-covered material, and anything belonging to another client.
Keep reading
Related reading
Done-for-you
Want guardrails your team will actually use?
We build the governance and operating model — permissions, risk tiers, data-handling rules and review cadence — then wire it into the workflows you already run and train your team on it. The same system behind a 4,000-person rollout that hit 72% weekly use in 30 days.
